Back to News
Market Impact: 0.35

China’s 360 says it has developed tools to match Anthropic’s Mythos

Artificial IntelligenceCybersecurity & Data PrivacyTechnology & InnovationSanctions & Export ControlsGeopolitics & WarRegulation & LegislationInfrastructure & Defense
China’s 360 says it has developed tools to match Anthropic’s Mythos

360 Security Technology said it has built two AI security tools, including "Tulongfeng," which it calls China’s version of Anthropic’s Mythos for finding software vulnerabilities. Zhou Hongyi said the system has found 3,432 vulnerabilities, including 105 confirmed by Chinese authorities, while acknowledging domestic AI models still lag U.S. rivals by 20%-30% in base capability. The article underscores China-U.S. tensions over cyber capabilities and export controls, but it is primarily a strategic technology development rather than an immediate market event.

Analysis

This is less a single-company story than a signal that cyber capability is becoming bifurcated by geopolitics: U.S. vendors will increasingly monetize “trusted” access in the West, while China builds a parallel stack optimized for domestic sovereignty and state-linked deployment. That is structurally supportive for incumbent security platforms with government distribution and services-heavy revenue models, because customers will pay up for audited workflows, incident response, and compliance rather than raw model performance. The immediate commercial winner is not necessarily the first company to find more vulnerabilities; it is the vendor that can package AI into defensible workflows without creating liability.

For IBM and PANW, the second-order effect is budget reallocation rather than pure demand creation. Enterprises are likely to shift spend toward detection, response, identity, and managed services as boards become more concerned that offensive AI tooling raises breach frequency and blast radius. PANW is better positioned to capture this than IBM because the former is already a security platform with direct leverage to AI-driven security spend, while IBM’s exposure is more diffuse and could be drowned out by slower infrastructure and consulting mix.

The market is probably underpricing the regulatory tail: once sovereign AI-security tools become strategic assets, export restrictions, procurement rules, and disclosure requirements can compress the addressable market for cross-border cybersecurity software over a 6-18 month horizon. The contrarian view is that the biggest beneficiaries may be the less obvious operators selling “picks-and-shovels” around governance, logging, and response automation, not the headline AI model vendors. Near term, however, any escalation in AI-enabled cyber rhetoric should support the premium multiples of large-scale security platforms, because it reinforces the narrative that cybersecurity is becoming a non-discretionary infrastructure spend.

More News